TISAX®: Assessment, Label, and What Can Be Automated

Author
Dr. Kilian Schmidt
Date
4.6.2025
Updated on
19.8.2026
TISAX®: Assessment, Label, and What Can Be Automated

TISAX® is how automotive suppliers demonstrate their information security. When an OEM or a larger supplier asks for that proof, you go through an assessment and receive a label. This article covers how the framework is structured, where the work actually sits, and which parts of it can be automated.

Who requires TISAX®

TISAX® was established by the German Association of the Automotive Industry (VDA) and is administered by the ENX Association.

Most European OEMs require TISAX® of their direct suppliers, and those suppliers require it of their own. The obligation travels several tiers down a supply chain, so it can reach you without an OEM ever contacting you directly.

What TISAX® is for

TISAX® standardizes information security assessment against the VDA ISA catalog, which is itself derived from ISO 27001.

The point of the exchange is mutual recognition. Once you complete an assessment, the result is shared with your customers through the ENX portal, so you do not repeat a full security audit for every OEM that asks. Suppliers who complete an assessment receive a TISAX® label, valid for three years.

Assessment levels and objectives

TISAX® has three assessment levels with increasing requirements:

  • AL1: self-assessment, rarely accepted by OEMs
  • AL2: assessment for high protection needs
  • AL3: assessment for very high protection needs, normally required for prototype protection

There are also three main assessment objectives:

  1. Information security: core requirements based on ISO 27001
  2. Prototype protection: measures protecting prototype vehicles and components
  3. Data protection: requirements for handling personal data under the GDPR

Each level and each objective brings its own evidence requirements, and they overlap. The same control can fall under more than one objective, with a different depth expected each time. This is where manual tracking starts to strain.

The three problems with managing TISAX® manually

Whatever the size of the supplier, manual management runs into the same three problems.

The first: evidence has to be current, not merely available. An assessment checks whether your controls were operating during the period under review. A screenshot taken eight months ago proves what was true eight months ago.

The second: the evidence does not sit in one place. Access logs are in your identity provider, training completions in your HR system, device inventories in your endpoint tool, supplier contracts on legal's drive. Someone has to open each of those systems, export what is needed, and keep track of which version they exported.

The third: TISAX® does not end. Labels expire, your scope shifts as you win customers with different protection needs, and controls drift because your systems change. A folder that was accurate on assessment day is out of date within months.

What can be automated

Evidence collection and management

An automation platform can connect directly to your systems and pull evidence, rather than having someone export it by hand. It standardizes the formats so assessors accept them, and it keeps a history you can use to demonstrate that a control operated continuously rather than on the day someone checked.

Cross-functional workflows

A TISAX® implementation pulls in IT, engineering, HR, legal, procurement and production. Coordinating between those functions is often the slowest part of the project.

Automation helps here through:

  • role-based assignment of responsibilities
  • automatic task distribution and reminders
  • central progress tracking you can read at any time

Prototype protection

AL3 assessments impose particularly strict prototype protection requirements. What is asked for is not only security technology but complete traceability of access, use and handling across the development lifecycle.

In practice: for any prototype file or physical part, you need to be able to say who accessed it, when, and under whose approval. If finding that out takes three phone calls, it is not traceability.

How suppliers go about it

From manual to automated

Suppliers who start out managing TISAX® manually and later automate tend to follow the same order:

  1. Process analysis: document the existing manual processes
  2. Targeted automation: identify the expensive, repeatable processes to start with
  3. Gradual extension: evidence collection first, then the rest

Automating prototype protection

Suppliers whose scope includes prototype protection at AL3 face a narrower and harder problem than general information security. The approach that holds up focuses on three things:

  1. Continuous monitoring of access to prototype data and how it is used
  2. Digital approval workflows for access requests
  3. Logging of all prototype-related activity

Your TISAX® automation roadmap

Step 1: assess your requirements and current state

Start by working out which assessment level and which objectives apply to you.

The most common and most expensive mistake at this stage is scoping too wide. Implementing controls beyond what your customers actually require costs real effort and earns you no additional label.

Document where you stand on:

  • implementation status of your security controls
  • evidence collection processes
  • relevant systems and data repositories
  • cross-departmental workflows

Step 2: prioritize what to automate

Start with the tasks that recur and have clear inputs and outputs. Those automate cleanly. Tasks that require professional judgment do not, and trying to tackle those first is why automation projects stall.

The usual candidates:

  • evidence collection from your security and IT management tools
  • tracking and documenting policy acceptance
  • access control monitoring and logging

Step 3: choose technologies and partners

Generic compliance tooling usually covers the information security objective adequately, then falls short on prototype protection, because there is no equivalent in ISO 27001. Ask about it specifically.

Other criteria:

  • pre-built TISAX® control catalogs and assessment templates
  • integrations with the security and IT tools you already run
  • supplier management features, if you have to assess your own supply chain

Step 4: roll out in phases

Do not automate everything at once. A sequence that works:

  1. Foundation: core platform and document repository
  2. Evidence collection: connect the main systems
  3. Workflows: cross-departmental processes and approvals
  4. Extension: analytics and continuous monitoring

Conclusion

Automation is an investment. The return shows up as less scrambling in the weeks before an assessment, and as fewer controls that quietly lapse between them.

If your scope widens because a new customer arrives with a higher protection need, you extend an existing system rather than starting over.

Kertos automates the evidence work behind TISAX®, ISO 27001 and the GDPR on one platform. Book a time if you want to see what that looks like for your scope.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder at Kertos

Kilian had a strong focus on legal processes from an early age and began his career at Home24 as a Senior Legal Counsel and Data Protection Officer for the Home24 group. After a stint at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where he expanded the company's legal and public policy departments from one to 65 cities and from 50 to 800 employees. Driven by the lack of technology in the legal field and confirmed by his consulting work at Gorillas Technologies, he decided to found Kertos to develop the next generation of compliance – made in Europe.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check